OTSecurity

ENISA Threat Landscape 2026 highlights ransomware, vulnerability exploitation, AI-enabled attacks across EU organizations


Ransomware attacks remain the most damaging cyber threat facing the European Union, with operators continuing to disrupt organizations across multiple sectors through encryption, data theft, and extortion-based operations, according to European Union Agency for Cybersecurity (ENISA) Threat Landscape 2026 report analyzing incidents from 2025. Public administration accounted for 32% of all targeted organizations, followed by business services and manufacturing at 8% each, with 73% of victims classified as essential or important entities under EU regulations. Cybercrime encompassed 36% of total incidents, with ransomware deployment accounting for 40% of financially motivated activities, data breaches for 31%, and fraud and impersonation comprising 19%. Social engineering tactics, including phishing campaigns and the ClickFix technique, remained prevalent enabling mechanisms for attacks.

Threat landscape expanded significantly across multiple vectors, with hacktivists launching 4,709 campaigns against EU Member States during 2025, more than 89% involving disruptive DDoS attacks tied to geopolitical tensions, political developments, and elections. Ideology-driven incidents accounted for 57% of threats targeting the EU, while 30% were financially motivated. 

The publication of over 48,000 new vulnerabilities, a 22% increase from the prior year, coupled with exploitation data showing 60% of unauthorized access incidents leveraged known vulnerabilities, underscored persistent security gaps. Threat groups increasingly integrated artificial intelligence to enhance malicious activities and expand operational reach, while supply-chain and third-party attacks continued to result in large-scale incidents affecting critical infrastructure and digital services.

“The ENISA threat landscape is more than a list of cybersecurity threats affecting the EU and how they are distributed around sectors and entities,” Juhan Lepassaar, ENISA’s executive director, said in a media statement. “The analysis highlights how threats become more interconnected and how threat groups spread their impact across the larger map of digital services and infrastructures. Being aware of such underlying dynamics is key if we want to implement the right solutions and maintain a high level of resilience across our digital economy.”

The ENISA Threat Landscape 2026 revealed that DDoS attacks (51.3%) and unauthorised access (39.5%) continued to account for a large share of the recorded activity affecting EU Member States and EU-based organisations. Social engineering remained a common enabling tactic to abuse trust, particularly through phishing campaigns (77.8%), increasingly supported by phishing kits and service-based ecosystems. Exploitation of vulnerabilities, including N-day and 0-day vulnerabilities, also remained a prevalent intrusion vector to enable unauthorised access (60.4%). 

At the same time, supply chain targeting, third-party providers, cloud environments and other cyber dependencies continued, resulting in impactful and large-scale incidents. Financially motivated activities (29.3% of all recorded incidents), particularly ransomware, remained the most impactful incidents in the short-term. Ransomware, data breaches, phishing and fraud impacted a broad range of sectors, reflecting the continuing adaptability of the cybercrime ecosystem. 

ENISA identified that manufacturing, business services and public administration were among the sectors most affected by cybercrime-related activities. Across the reporting period, ransomware operators continued relying on extortion and data exposure through public claims shared on Data Leak Sites (DLS) and dark web forums, while fraud and phishing activity highlighted the continued importance of credential compromise, impersonation and social engineering techniques, notably through the increased use of ClickFix and SMS phishing (smishing). 

Geopolitical developments such as the continuation of Russia’s war of aggression against Ukraine or the conflict escalation in the Middle East continued to influence cyber activity impacting the EU. Ideology-driven operations represented a significant share of the observed activity (57.3%), particularly through hacktivist-led DDoS campaigns targeting public-facing services, essential entities and organisations associated with political developments or support for countries such as Ukraine or Israel. 

The ENISA Threat Landscape 2026 documented state-nexus intrusion sets conducting cyberespionage and financially motivated campaigns, with Russian-nexus groups primarily targeting central governmental and diplomatic entities while China-nexus intrusion sets showed continuous interest in the transport sector, including maritime entities. 

State-nexus actors relied predominantly on unauthorized access (81.7%) and phishing campaigns (12%), though ENISA identified initial intrusion vectors in only 20% of incidents, of which vulnerability exploitation accounted for 70%. The increase in insider threats (5%) represents a particular concern, while approximately 1.5% of cyberespionage activities remained unattributed. Attribution data showed Russian-nexus intrusion sets accounting for 47.6% of identified state-nexus activity, followed by China (15.5%), North Korea (14.1%), and Iran (9%).

2025 confirmed the continued exposure of sectors to cyber threats, including sectors of high criticality according to NIS2. Public administration remained the most impacted sector (31.8%), followed by business services (8.5%), transport (8%), manufacturing (6.9%) and finance/banking (5.6%). Sectoral analysis further highlighted differences in targeting patterns, threat groups and operational impact across sectors, notably showing the criticality of digital dependencies, sensitive data holdings and operational maturity in shaping exposure to cyber threats. 

Another notable development throughout the reporting period was continued adaptation of threat groups’ operational playbooks. Cybercriminal, hacktivist and State-nexus threat groups increasingly relied on scalable techniques, shared tooling patterns and trusted digital environments to conduct malicious activities. 2025 also observed the continued integration of artificial intelligence into malicious cyber activities, including activities carried out by cybercriminal operators, State-nexus intrusion sets and Information Manipulation Sets (IMS). 

The ENISA Threat Landscape 2026 reported that Russia employed Foreign Information Manipulation and Interference (FIMI) as a core state power instrument in 2025, strategically shifting focus from the U.S. to concentrate on Europe. Russian FIMI campaigns accompanied escalatory hybrid actions including drone incursions, sabotage, and critical infrastructure attacks across Poland, Romania, Lithuania, and Estonia, designed to manage public perception and test EU responses. The Kremlin’s operations, tailored to specific audiences, aimed to deepen existing divisions and mobilize anti-establishment sentiment by portraying the EU as either undemocratic and aggressive or dangerously weak, with EU leaders and institutions as primary targets.

Looking ahead, the ENISA Threat Landscape 2026 assesses that several dynamics observed in 2025 are likely to persist into the next reporting period. Organisations across the EU will continue facing a combination of cybercrime, cyberespionage and hacktivist activity driven by geopolitical developments. While objectives remain distinct, cybercriminal, hacktivist and state-nexus operators increasingly rely on similar access vectors, tools and operational approaches, making imputation and threat analysis more challenging. 

Cybercrime is expected to remain one of the most significant sources of disruption to organisations operating in the EU, supported by mature criminal ecosystems, evolving extortion models and the continued availability of specialised services and tooling. The reporting period also reinforced importance of digital dependencies, as incidents affecting software suppliers, service providers and cloud environments continued to demonstrate potential for broader downstream impact. 

The ENISA Threat Landscape 2026 report assesses that artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations. It is also likely that 2026 will see an increased number of the kill chain’s phases being directly enabled by AI, with possible experimentation of human-out-of-the-loop proof of concepts. 

Growing availability of frontier AI models and specialised malicious or dual-use tooling has already demonstrated its impact in augmenting the development of malicious capabilities and will likely lower barriers to entry into malicious cyber activities and further support scaling, automation and velocity across cyber operations. It is also likely that the use of these new models will increase EU organisations’ exposure to new threats, arising from both accidental and malicious activities.



Source link